Research Article
Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes
Table 3
Results of the attack against ECOC for MNIST classification.
| Parameters | Proposed (ECOC) | C&W (ECOC) | C&W (one-hot) | ASR (%) | PSNR | ASR (%) | PSNR | ASR (%) | PSNR |
| (1e − 3, 10, 100, 0) | 29.3 | 21.26 | 26 | 21.19 | 1.5 | 32.48 | (1e − 3, 10, 200, 0) | 43.6 | 21.49 | 35.6 | 20.73 | 8 | 27.69 | (1e − 3, 10, 500, 0) | 55.6 | 21.91 | 43.6 | 20.37 | 40.5 | 24.29 | (1e − 3, 10, 1000, 0) | 64.6 | 22.23 | 49 | 20.56 | 66.5 | 24.97 | (1e − 1, 10, 2000, 0) | 72.3 | 22.35 | 57.6 | 20.35 | 78 | 25.29 |
|
|
Reported parameters indicate, respectively (start point, number of steps of binary search, max iterations, confidence).
|